<< Prev Question Next Question >>

Question 81/151

When integrating information security requirements into software development, which of the following practices should be FIRST in the development lifecycle?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (151q)
Question 1: For an organization with operations in different parts of th...
Question 2: Communicating which of the following would be MOST helpful t...
Question 3: An organization has purchased a security Information and eve...
Question 4: What should be an information security manager's BEST course...
Question 5: The PRIMARY focus of a training curriculum for members of an...
Question 6: Which of the following should be an information security man...
Question 7: Which of the following would be MOST effective in preventing...
Question 8: The BEST way to establish a security baseline is by document...
Question 9: After adopting an information security framework, an informa...
Question 10: A data leakage prevention (DLP) solution has identified that...
Question 11: Which of the following provides the MOST essential input for...
Question 12: What is the MOST important role of an organization's data cu...
Question 13: When scoping a risk assessment, assets need lo be classified...
Question 14: A risk has been formally accepted and documented. Which of t...
Question 15: An organization with a strict need-to-know information acces...
Question 16: An information security manager learns that a departmental s...
Question 17: Which of the following is the BEST option for addressing reg...
Question 18: When preparing a risk treatment plan, which of the following...
Question 19: A third-party service provider is developing a mobile app fo...
Question 20: The PRIMARY purpose of a periodic threat and risk assessment...
Question 21: When monitoring the security of a web-based application, whi...
Question 22: Which of the following is the MOST important consideration w...
Question 23: Which of the following is the BEST evidence of an effectivel...
Question 24: When two different controls are available to mitigate a risk...
Question 25: When establishing an information security strategy, which of...
Question 26: When a critical incident cannot be contained in a timely man...
Question 27: A security team is conducting its annual disaster recovery t...
Question 28: Which of the following is MOST helpful for aligning security...
Question 29: Risk identification, analysis, and mitigation activities can...
Question 30: Which of the following BEST determines an information asset'...
Question 31: Which of the following is the BEST way to determine if an in...
Question 32: An information security manager finds that corporate informa...
Question 33: In a resource-restricted security program, which of the foll...
Question 34: From an Information security perspective, legal issues assoc...
Question 35: Segregation of duties is a security control PRIMARILY used t...
Question 36: Which of the following would provide the BEST justification ...
Question 37: When trying to integrate information security across an orga...
Question 38: Which of the following is an indicator of improvement in the...
Question 39: Which of the following is the BEST way for an information se...
Question 40: The use of a business case to obtain funding for an informat...
Question 41: An incident was detected where customer records were altered...
Question 42: The MAIN consideration when designing an incident escalation...
Question 43: Which of the following is MOST effective in reducing the fin...
Question 44: An information security manager is reviewing the organizatio...
Question 45: Which of the following should provide the PRIMARY justificat...
Question 46: Which of the following is MOST appropriate to include in an ...
Question 47: Which of the following is MOST helpful to developing a compr...
Question 48: Which of the following metrics would BEST monitor how well i...
Question 49: A corporate web site has become compromised as a result of a...
Question 50: Which of the following trends BEST indicates that the maturi...
Question 51: Several identified risks have been mitigated to an acceptabl...
Question 52: The MOST effective way to communicate the level of impact of...
Question 53: Which of the following MOST effectively helps an organizatio...
Question 54: What should an information security manager do FIRST when a ...
Question 55: Which of the following is the MAIN concern when securing eme...
Question 56: Which of the following is the BEST way to prevent recurrence...
Question 57: Which of the following would BEST demonstrate the maturity l...
Question 58: Which of the following should be an information security man...
Question 59: Which of the following should be the FIRST step of incident ...
Question 60: When considering whether to adopt a new information security...
Question 61: An inexperienced information security manager is relying on ...
Question 62: An organization has established information security policie...
Question 63: The MOST important objective of security awareness training ...
Question 64: Which of the following should be the MOST important consider...
Question 65: Which of the following models provides a client organization...
Question 66: The MAIN purpose of documenting information security guideli...
Question 67: When considering whether to adopt bring your own device (BYO...
Question 68: Which of the following is the PRIMARY reason an information ...
Question 69: Which of the following provides the GREATEST assurance that ...
Question 70: Which of the following is the MOST important reason to docum...
Question 71: An attacker was able to gain access to an organizations peri...
Question 72: Which of the following provides the BEST indication that the...
Question 73: Which of the following is MOST important when establishing a...
Question 74: The criticality of an information asset is derived from its:...
Question 75: Which of the following is the MOST relevant risk factor to a...
Question 76: Which of the following should an information security manage...
Question 77: Which is MOST important when contracting an external party t...
Question 78: In a large organization requesting outsourced services, whic...
Question 79: Which of the following is the MOST effective preventive cont...
Question 80: When facilitating the alignment of corporate governance and ...
Question 81: When integrating information security requirements into soft...
Question 82: Which of the following is the BEST reason to separate short-...
Question 83: In which of the following ways can an information security m...
Question 84: Which of the following should be of MOST influence to an inf...
Question 85: Which of the following should be the MOST important consider...
Question 86: Which of the following is MOST important to help ensure an i...
Question 87: When reporting on the effectiveness of the information secur...
Question 88: Which of the following is the MOST effective approach of del...
Question 89: The MOST important objective of monitoring key risk indicato...
Question 90: Which of the following is the BEST method to protect against...
Question 91: Which of the following should be the PRIMARY basis for deter...
Question 92: An application system stores customer confidential data and ...
Question 93: Which of the following is MOST important lo track for determ...
Question 94: The effectiveness of an information security governance fram...
Question 95: A core business function has created a significant risk. Bud...
Question 96: Which of the following provides a sound basis for effective ...
Question 97: Vulnerability scanning has detected a critical risk in a vit...
Question 98: An internal security audit has reported several control weak...
Question 99: The use of digital signatures ensures that a message:...
Question 100: Management is questioning the need for several items in the ...
Question 101: The PRIMARY reason for classifying assets is to:...
Question 102: Which of the following should cause the GREATEST concern for...
Question 103: A core business unit relies on an effective legacy system th...
Question 104: The MOSTimportant reason to maintain metrics for incident re...
Question 105: If the inherent risk of a business activity is higher than t...
Question 106: Which of the following is the MOST important reason for an o...
Question 107: The BEST way for an information security manager to understa...
Question 108: Which of the following is the MOST important criterion when ...
Question 109: Senior management is concerned a security solution may not a...
Question 110: An organization is planning to create a website that will co...
Question 111: An organization has detected sensitive data leakage caused b...
Question 112: What is the MOST effective way to ensure information securit...
Question 113: Which of the following is MOST important in the development ...
Question 114: Which of the following would BEST demonstrate the status of ...
Question 115: An information security manager has researched several optio...
Question 116: Which of the following is the MOST important reason to ident...
Question 117: An information security manager has been made aware that imp...
Question 118: What would be an information security manager's BEST recomme...
Question 119: Which of the following is MOST critical when creating an inc...
Question 120: Ensuring that an organization can conduct security reviews w...
Question 121: When conducting a post-incident review, the GREATEST benefit...
Question 122: Which of the following would BEST protect against web-based ...
Question 123: An organization has detected potential risk emerging from no...
Question 124: Which of the following would BEST enable effective decision-...
Question 125: Which of the following will BEST facilitate the development ...
Question 126: An organizations ability to prevent a security incident In a...
Question 127: Senior management has allocated funding to each of the organ...
Question 128: An information security manager wants to document requiremen...
Question 129: Which of the following would be an information security mana...
Question 130: Which of the following approaches would MOST likely ensure t...
Question 131: An organization has announced new initiatives to establish a...
Question 132: An information security manager has determined that the mean...
Question 133: A risk assessment has been conducted following a data owner'...
Question 134: Which of the following BEST helps to identify vulnerabilitie...
Question 135: Which of the following is the MOST important security consid...
Question 136: Which of the following would BEST help an information securi...
Question 137: An organization is considering moving lo a cloud service pro...
Question 138: Which of the following is the BEST reason to develop compreh...
Question 139: Following a significant change to the underlying code of an ...
Question 140: Which of the following is MOST important to the successful i...
Question 141: In a large organization, which of the following is the BEST ...
Question 142: Which of the following is the MOST important reason for logg...
Question 143: Which of the following BEST ensures timely and reliable acce...
Question 144: Which of the following is the BEST way for an information se...
Question 145: An organization has identified an increased threat of extern...
Question 146: Which of the following is a PRIMARY goal of an information s...
Question 147: Which of the following defines the triggers within a busines...
Question 148: Which of the following would be MOST helpful in gaming suppo...
Question 149: Which of the following is the MOST important function of inf...
Question 150: The BEST way to ensure information security efforts and init...
Question 151: Which of the following is the MOST effective way to mitigate...